--- title: "Chris and Robert -- Proactive Controls, AppSec USA, and Gartners MQ on AppSec Testing" url: https://appsecpodcast.com/chris-and-robert-proactive-controls-appsec-usa-and-gartners-mq-on-appsec-testing/ date: 2017-08-17 duration_seconds: 1369 topics: ["OWASP Top 10", "Security Testing"] audio: https://www.buzzsprout.com/1730684/episodes/8122712-chris-and-robert-proactive-controls-appsec-usa-and-gartners-mq-on-appsec-testing.mp3 transcript: true --- # Chris and Robert -- Proactive Controls, AppSec USA, and Gartners MQ on AppSec Testing *August 17, 2017 · 23 min* on [OWASP Top 10](https://appsecpodcast.com/topics/owasp-top-10/), [Security Testing](https://appsecpodcast.com/topics/security-testing/) [Audio](https://www.buzzsprout.com/1730684/episodes/8122712-chris-and-robert-proactive-controls-appsec-usa-and-gartners-mq-on-appsec-testing.mp3) ## Show notes What can practitioners learn from a new OWASP document, an upcoming conference, and an industry analyst report in one conversation? Chris and Robert test a multi-topic format by reviewing Proactive Controls 3.0, previewing AppSec USA, and discussing Gartner’s application security testing market analysis. They examine renamed controls, digital identity guidance, conference learning and hallway conversations, and the range of testing products covered by the report. The hosts compare static, dynamic, interactive, and runtime approaches while questioning predictions about adoption and unfamiliar vendors. The episode captures a moment in the market rather than offering timeless rankings, but its method remains useful: read frameworks and analyst material critically, understand what each category measures, and investigate tools in the context of your own development program. The Application Security Podcast is brought to you by [Security Journey](https://www.securityjourney.com/). About Security Journey Security Journey provides application security education for developers and everyone in the software development lifecycle. → [Learn more about Security Journey](https://www.securityjourney.com/) Connect with Chris Romeo and Robert Hurlbut: → [Chris Romeo on LinkedIn](https://www.linkedin.com/in/chrisromeo-appsec) → [Robert Hurlbut on LinkedIn](https://www.linkedin.com/in/roberthurlbut) Mentioned in this episode: → [OWASP Proactive Controls](https://top10proactive.owasp.org/) → [OWASP Proactive Controls](https://owasp.org/www-project-proactive-controls/) → [OWASP Threat Dragon Project](https://owasp.org/www-project-threat-dragon/) → [Contrast Security](https://www.contrastsecurity.com/) Chapters: 00:00 Three AppSec topics in one episode 01:36 OWASP Proactive Controls 3.0 02:58 Renamed and reorganized controls 04:15 Strong digital identity 05:36 Why AppSec USA matters 08:19 Fundamentals and advanced conference content 11:01 Meeting the podcast community 12:52 Gartner’s application security testing report 14:13 Predictions about testing adoption 16:36 Interactive and runtime testing 18:46 Unfamiliar vendors in the market 20:27 Using analyst reports as a starting point 22:34 Closing thoughts ## Transcript *4,028 words · assemblyai* **0:05 Chris Romeo:** The Application Security Podcast. Here we go. Hey folks, this is Chris, and on this episode of the Application Security Podcast, Robert and I are trying a new format where we're going to talk about a couple of different topics in a little bit of a shorter burst. So on this episode, we're going to talk about some upcoming changes that are happening to the Proactive Controls Project at OWASP. We're going to talk about AppSecUSA, and then we'll finish the conversation speaking about the new Magic Quadrant for application security. I guess the first thing I wanted to bring up in our conversation here is the OWASP Proactive Controls. We've mentioned the proactive controls a couple of times in the last few episodes when we had Dave come on and talk about— he really focused us in on the actual proactive controls and took us through the document and explained it to us. Then we had Jim Manico on, and he's one of the project leads for proactive controls. He also made some references to it and brought it back into our attention as well. So I guess one of the big things that's happening is I just heard there's a new update to the Proactive Controls. **1:36 Robert Hurlbut:** Right. So the previous version was 2.0, so the latest one is now 3.0. Just came out, as you mentioned, today, announcement that it's been generally available for review for everyone to take a look at it and make some comments. **1:55 Chris Romeo:** Yeah, which is kind of the OWASP way to put stuff out there and then let other people kind of have a chance to take a look at it and see, you know, what, uh, what, what they might be able to think about the changes. Um, as I'm scanning down the list of the changes here and looking at the document, and just so folks know, the Proactive Controls, they're making this update as a public Google Doc that anybody can add comments to and anybody can suggest changes to kind of in real time. So if you If you do want to go take a closer look at this, we'll make the link available based on what we know it to be as of today on the posting for this episode. Folks can actually go take a look at this themselves. If you see something or if you want to contribute to it, once again, it's OWASP, it's open source, it's free to use, but that also means that there's no one behind the scenes who's making millions of dollars for creating and working on this project. Folks can go ahead and go take a look at it themselves. If I look at the a couple of the changes that I'm seeing now. It looks like they renamed the first one, um, Build Security into Software Early and Intentionally. **2:58 Robert Hurlbut:** Yeah, that looks right. It seems— I mean, it's similar to what it was, but it is definitely renamed. **3:05 Chris Romeo:** Yeah, so they— I think they added some of that intentionally thing to it. Um, the second— so they've added— they've changed one of them into this, this idea of Secure Database Access. So instead of kind of focusing in on SQL injection, it almost seems like they've taken a step back and are now taking a more general approach to dealing with databases versus just hyper-focusing on SQL injection. **3:28 Robert Hurlbut:** Interesting that, as you mentioned, before it was parameterized queries, now it's secure database access. That seems like it may include quite a few more things. **3:40 Chris Romeo:** Yeah. It looks like they're still in the process of working through what the additions are going to be to that. But still, I think it's going in the right way. I've been a huge proponent of this document in general since I saw it, and we've been talking about it here more on the show. I think it's something that's very underutilized as well in the industry. **4:02 Robert Hurlbut:** Right. Well, there's still a lot of people that don't know about it. I've talked to several, and they know about the OWASP Top 10, but not about the proactive controls, which is, again, why we keep talking about it, trying to get the word out. **4:15 Chris Romeo:** Yeah. So did they change up this 5th one as well? It says implement strong digital identity. **4:19 Robert Hurlbut:** Yeah, that looks different. **4:21 Chris Romeo:** Yeah, I think it used to be something about authentication or whatever that it was focused on. **4:25 Robert Hurlbut:** Right. **4:26 Chris Romeo:** So yeah, I mean, I think we can just encourage our listeners that are already involved in AppSec to go out and take a look at this document and see kind of what you might be able to recommend or what you can learn based on the changes. But we recommend that folks get out there and actually contribute along the way. So I guess the second thing, Robert, I wanted to talk about is there is an upcoming conference that is put on by the good folks at OWASP called AppSec USA. And since we are the AppSec Podcast, it almost seems like we should talk about AppSec USA and kind of what that is. So have you had a chance to attend AppSec USA before? **5:08 Robert Hurlbut:** Yes, I've been to a couple of them. It's really a great conference. I enjoy it. I enjoy meeting some people that are coming from all over the country and sometimes even from Europe and other places as well. But it's definitely a good place to be for application security enthusiasts to learn some things about application security. Lots of great talks, definitely also lots of great opportunities in the hallways to meet people and talk about these topics. **5:36 Chris Romeo:** Yeah, we were talking about that last week in reference to your experiences at Black Hat about how the hallway conversations is almost as great as the talks and things that you'll experience and kind of the learning side. So conferences and AppSecUSA is no different. The relationships that you can build by being there in that environment is just huge because you can meet people that you might follow on Twitter, for example. I think that's a blast to me when I'm at a conference and I connect with somebody who I've communicated with back and forth on Twitter for years and have never had the chance to actually shake hands with and say hello to in person. It's just really fun to connect with people in that way. **6:22 Robert Hurlbut:** Yeah, I agree. I've done the same thing where we talk on Twitter, we message, we go back and forth and then find out, hey, they're at this conference. Let's go meet and get a coffee or lunch or something. And yeah, that's, it's a great, great thing to be able to connect with people face to face and not just over email or Twitter or something like that. **6:43 Chris Romeo:** Yeah, I'm remembering like you and I, we actually met for the first time at AppSec USA. **6:48 Robert Hurlbut:** I was thinking that too. **6:49 Chris Romeo:** In San Francisco, right? That was 2 years ago. **6:52 Robert Hurlbut:** Yeah. **6:52 Chris Romeo:** So that's, I mean, and so that's kind of this, this podcast probably never would have happened if you and I hadn't actually had a chance to connect after a talk that I did at AppSec USA that year. And that was kind of what started us chatting back and forth and looking for ways to work together. And then this podcast kind of came out of that experience. So I think that's actually, that's another good positive of what can come out of just going and meeting people. **7:18 Robert Hurlbut:** Yeah, agree, agree. I was thinking the same thing. I thought, you know, it was, it was 2 years ago in San Francisco that right after your talk we met. Yeah. **7:26 Chris Romeo:** And so I'm kind of scanning the AppSecUSA program and website stuff for this year. And, you know, they definitely, there's some really good stuff that's gonna be happening there. Jim Manico, is one of the keynote speakers who was with us a few weeks ago. Jen Ellis, InfoSec Jen from Rapid7, she's going to be another one of the keynotes. They got a few other folks, and AppSecUSA always has a great mix of technical. They focus heavily on the technical side of application security and people that are solving problems. They do a little bit of the vulnerability perspective and challenges and things that people are uncovering through the vulnerability process, but they really do have a lot of good stuff on AppSec programs and case studies and things where people have been successful. So I've always enjoyed to be a consumer and sit in and listen to a lot of the talks that happen at AppSec USA. **8:19 Robert Hurlbut:** Yeah, me too. I think that, I mean, there's, like you said, there's quite a range of talks and discussions that happen in terms of fundamentals. I like those when you have some people that may be new, they need to learn those as well. And then some more deep dives. I like those and seeing those in there, and then anything in between. So you get quite a bit of options when you go to a conference like this. And the other thing I like, you know, different from a Black Hat or a DEF CON, especially for us in application security, is it is application security. It's not network, it's not, you know, infrastructure. It's really focused on application security. **9:05 Chris Romeo:** Yeah. **9:05 Robert Hurlbut:** from many ranges there, as we mentioned. And so, yeah, it's a great place to be. Yeah. **9:12 Chris Romeo:** And I'm just once again scanning the list of potential talks, and I probably shouldn't be clicking on things that I want to see here at this point, but I kind of was. Just so folks know, so AppSec USA takes place this year in Orlando, Florida, and the conference runs from Tuesday, September 19th through Friday, September 22nd. And what they do at AppSec USA is for Tuesday and Wednesday, they actually do training classes. Whoa, Robert, did you just drive off on your Harley there right in the middle of the podcast? **9:41 Robert Hurlbut:** No, I came back. I'm here. **9:44 Chris Romeo:** He's been on his— he's been riding on his Harley all day long here. Just kidding, folks. So on Tuesday and Wednesday at AppSec USA, they do a series of different training sessions that are happening 1 and 2 days. And I'll actually be doing an AppSec Fundamentals training class on Wednesday, September 20th. @AppSecUSA. This class is aimed at those that are new, a lot of the people we're trying to reach here in our podcast, folks that have an interest in AppSec, but maybe they have a development background or a sysadmin background, but they don't have the actual kind of foundational understanding. So that's what I'm going to be focusing on. And Robert, I know you're going to be doing something at the Developer Summit, right? **10:22 Robert Hurlbut:** Correct. Yeah, I'm going to be speaking on Tuesday, Developer Summit morning session. My topic is going to be actually something we've also talked about here on Application Security Podcast about threat Taking a look at that threat modeling and Threat Dragon. I'll be doing a workshop on that, and that's, you know, Mike Goodwin talked about that with us, Threat Dragon, and so it'll be a nice introduction just to people to understand what it is, and as well as I'm going to talk about some threat modeling in there. And there are several other options there at this conference which I'm really looking forward to as well on threat modeling, but that's my particular offering on Tuesday morning. **11:01 Chris Romeo:** Yeah, and that's exciting and encourage folks to get out. And if you're at the conference, Robert and I, like we just alluded to, are both going to be there. So we'd love to meet anybody who actually listens to the AppSec Podcast. We'd love to meet anybody, but we'd also really like to meet anybody who actually listens in on this podcast, regular listeners. And so yeah, pay attention on Twitter to the AppSec Podcast Twitter. We may schedule an impromptu meetup or something depending on how many people we learn that are running around AppSec USA. We'd love to meet as many of you as possible and hear your feedback on the show and any suggestions you'd have for things we could do in the future as well. The 3rd topic, Robert, I wanted to talk about relatively quickly is there was a— the good folks at Gartner put out this Magic Quadrant types of industry analyses. And they just released one on— it's called the Magic Quadrant for Application Security Testing. And we've talked with our listeners here quite a bit about the different types of application security testing that's out there, but I think it's important to take a second and kind of dig a little bit into what Gartner's saying and kind of how they're referencing the different types of technologies and where they see the players because It does give you some idea as to who you can look at if somebody's listening to this and they're thinking, hey, I want to— we don't have any application security testing engaged in our program and we want to get some. This is a way that you can kind of learn some things about what's out there in the industry and you can kind of figure out, hey, what type of company should I be looking at and what type of solution should I be looking at? **12:52 Robert Hurlbut:** Right. So yeah, it seems that it profiles some of these companies, it profiles some of their products and some of the things that they're offering. And so it's an interesting report. **13:03 Chris Romeo:** Yeah, I think the— I like to start looking at— in a lot of these reports, they do the strategic planning type of things and they tend to throw out some numbers there. And that can help people like us that are heavily involved in AppSec and we're always looking for statistics to throw around. I mean, they're saying by 2019, 80% of application security testing vendors will include software composition analysis in their offerings, up from 40% today. So basically, the vendors are going to be modifying their technology to be able to analyze what actually exists on the inside of the software. But the other big thing they're showing is by 2019, enterprise interactive application security testing will have exceeded 30%, and then they're saying RASP, the Runtime Application Self-Protection, will be no more than 10%. So they're, they're, they're saying that there's going to be some penetration in the markets based on these new types of technologies, but it's not going to be as prolific as something like static analysis or dynamic analysis. **14:04 Robert Hurlbut:** Which is interesting because I know we've also talked about that in relation to the OWASP Top 10 in terms of building some of those protections in. **14:13 Chris Romeo:** So here, this is predicting that it's still not going to be adopted Yeah, and I think that's a lot of reason why the OWASP Top 10, the new release candidates, and with the new management that that program is under, they have said that they're going to remove number 7 from— that exists in the release candidate, which was the need for basically application self-protection. They decided that's such a politically motivated— we've talked about that at length here too, but it's such a politically motivated and charged type of issue that they're just going to yank it out. I think Gartner's kind of backing them up here to some degree. **14:47 Robert Hurlbut:** Interesting. **14:49 Chris Romeo:** Just as a reminder, Gartner, when they're talking about application security testing, they're talking about static application security testing. This is the type of tools that are going through and looking at— they're scanning the source code, the bytecode, or the binary code, looking for different security vulnerabilities that exist. This is something that's normally done while the code's actually being written. It's something that's really good to do on a cycle. And then they talk about dynamic application security testing. So this is software that's going to be testing the— when the software is actually running itself. So it's, it's kind of like a vulnerability scanner, but in much more depth in that it has a lot of knowledge and understanding about how the application is working itself, and it then is able to look for different types of well-known vulnerabilities, especially in the web app space like the OWASP Top 10 issues. It's able to automate the hunt for those in the actual running operational software. And the last one is this new category that's the interactive application security testing. And the general idea here is you're gonna, you're gonna put some type of a module of software that's provided by a third-party vendor You're going to include that inside of your application. And when your application is running, this other security software is going to also be running. You can think of it as running inside your application. And what that, what that interactive IAST software is doing is it's actually searching for vulnerabilities from the inside of the application where it has access to all the data that's moving in different directions. And it really has a unique vantage point from kind of within the running application itself. **16:36 Robert Hurlbut:** So the difference between this and a runtime is it's inside the application versus something outside running and monitoring? **16:44 Chris Romeo:** Yeah, I think that's a good way to understand it. I don't have a lot of experience with RASP, and that's probably something that we probably need to do an episode just on these 3, specifically on the interactive AST versus the RASP tools. It would be a great episode for us to do up in the future so we can learn even more about how these 2 things kind of fit together. **17:05 Robert Hurlbut:** Yeah, that would be good because I'm curious now we're talking about it, what are the differences? What are the similarities? **17:12 Chris Romeo:** Yeah, and then so the other thing to know about these Magic Quadrant type reports that Gartner does, so they basically— if you've never seen one of these charts, you got to go to Google Images and just type in Gartner Magic Quadrant. It's a four. It's a it's a kind of it's a chart that has basically four different boxes that make up one big giant box, and they measure these individual companies based on one axis as on their ability to execute, and then the other axis is their completeness of vision. So what this is basically telling you is the more mature companies that have a strong vision and are are likely going to. Be around for a long time, they have an established kind of track record, are going to tend to fall into their top right quadrant, their leaders sector. And then their challengers on the, on the top left kind of quadrant here, these are going to be people that are— maybe they don't have as complete of a vision, but they do, they do have that track record that they'll be able to execute. And then the bottom right gives you these— this idea of visionaries. These are the people that have a great vision but maybe not as good of a of a track record in execution. And then the niche players fall into that bottom left where these are, these are kind of people that are on the fringe of this industry. And if we kind of look at where people fell into from different vendors in this particular space, most of the folks in the bottom left and the niche players, I don't really even recognize those. Did you recognize anybody? I guess I know PortSwigger because they make Burp Suite, but I didn't recognize anybody else in that list. Did you? **18:46 Robert Hurlbut:** I did not. That was the one I did not recognize, PortSwear. **18:50 Chris Romeo:** Yeah, so that kind of tells you, you know, Robert and I are both heavily engaged in the application security world, and most of the companies in that niche player we haven't even heard of before or have not had any interaction with. Whereas I can say everybody in the visionaries, leaders, and challengers, I know those companies and I know what they do. And so if you look at the visionaries, that's The only company that appears in that box is Contrast Security. This is Jeff Williams' company that is focused on their Contrast platform that does the IAST stuff. The challengers, you got people like Checkmarx and Qualys and Acunetix. These are companies that are doing a mixture of static and dynamic and maybe even getting into some of the interactive testing capabilities now. And then the leaders is kind of the standard people you'd think of that you'd find there. This is HPE, Veracode, IBM, Synopsys, White Hat Security. These are the well-established people that have a good roadmap and good track record of delivery in this overall space. And then the rest of this document is really just— it does a breakdown of strengths and cautions based on each of these vendors. So, like I said, if you're somebody who's going to get into adding these types of tools into your suites and building them into your program, I mean, this is a good document that's done a lot of the research for you into what does the industry look like. I use these as tools just to stay abreast of what's happening and who are really the movers and shakers in any given industry, especially in the world of application security. **20:27 Robert Hurlbut:** Right. There are some names that we saw here that we don't know. It bears checking out, see what they're doing. I think this is a good way to find out. what others are doing out there in the industry. **20:42 Chris Romeo:** Yeah, I certainly agree with that. I mean, if I was actively looking to add some application security testing capability to an existing program that I was running, I certainly wouldn't shy away from the niche players. I would do some research into what their offerings are because a lot of times you've got a lot of innovation happening in the bottom half of the Gartner quadrants here in the niche players and visionaries because those are more likely going to be the startups in this space, and we know that startups are more nimble and they can just move faster and they can release software a lot faster than a lot of the big folks out there that have more established kind of release cycles and things. So definitely don't discount the bottom half of the quadrants of the niche or the visionaries. Take a look at all the different solutions and just weigh them together. based on what your needs are and what the types of tools are you think you're going to start with in your program. So yeah, I guess with that, Robert, this kind of draws to an end our first kind of experimental episode. So folks, I would encourage you to please hit us up on Twitter with the @AppSecPodcast Twitter handle. Tag us and let us know kind of what you thought of this new format, if you thought it was good, if you thought it was terrible. You won't hurt Robert's feelings. You will potentially hurt mine, but that's okay. I'll get over it over some amount of time. But we thank you for taking the time to listen to this today, and we look forward to meeting up with some of you at AppSec USA, and we just hope that you have a very secure rest of your day. Thanks for listening to the Application Security Podcast. **22:34 Robert Hurlbut:** Our intro music is 8-Bit Color and Foo by Boring and TJ, and the outro is Southern Delight by Stefan Kartenberg. **22:42 Chris Romeo:** You can find us on Twitter @AppSecPodcast or on the web at www.appsecpodcast.org. --- Source: https://appsecpodcast.com/chris-and-robert-proactive-controls-appsec-usa-and-gartners-mq-on-appsec-testing/